CVE-2026-18482: Klarso GmbH Neo-Mjs
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath values into shell commands, enabling arbitrary OS command execution when an AI agent is induced to invoke these tools. Commit 88c77fc fixes these vulnerabilities.
Affected products
- Klarso GmbH Neo-Mjs: before 88c77fc4 (fixed in 88c77fc4)
Published 2026-08-20. Last modified 2026-09-03.